CVE-2026-1584
published 2026-04-09CVE-2026-1584: A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.38%
69.1th percentile
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnutls28 | < gnutls28 3.8.12-1 (forky) | gnutls28 3.8.12-1 (forky) |
| langroid | langroid | >= 0 < 0.59.32 | 0.59.32 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa9.8CRITICAL
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
vendor_redhat·2026-02-09·CVSS 7.5
CVE-2026-1584 [HIGH] CWE-476 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
Statement: This IMPORTANT flaw in gnutls allows a remote, unauthenticated attacker to cause a Denial of Service. By sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value, an attacker can trigger a NULL pointer dereference, leading to a crash of gnutls-based TLS servers configured to issue NewSessionTickets.
Debian
CVE-2026-1584: gnutls28
vendor_debian·2026·CVSS 7.5
CVE-2026-1584 [HIGH] CVE-2026-1584: gnutls28
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 3.8.12-1)
sid: resolved (fixed in 3.8.12-1)
trixie: resolved
GHSA
GHSA-92xv-mw29-x4px: A flaw was found in gnutls
ghsa_unreviewed·2026-04-09
CVE-2026-1584 [HIGH] CWE-476 GHSA-92xv-mw29-x4px: A flaw was found in gnutls
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the server to crash and resulting in a remote Denial of Service (DoS) condition.
GHSA
Langroid has WAF Bypass Leading to RCE in TableChatAgent
ghsa·2026-02-02·CVSS 9.8
CVE-2026-25481 [CRITICAL] CWE-94 Langroid has WAF Bypass Leading to RCE in TableChatAgent
Langroid has WAF Bypass Leading to RCE in TableChatAgent
## Affected Scope
langroid
## Gadget
pandas_eval (langroid\agent\special\table_chat_agent.py:239)
handle_tool_message (langroid\agent\base.py:2092)
handle_message (langroid\agent\base.py:1744)
agent_response (langroid\agent\base.py:760)
response (langroid\agent\task.py:1584)
step (langroid\agent\task.py:1261)
run (langroid\agent\task.py:827)
## Security Impact
Remote Code Execution (RCE) via `pandas_eval` tool. Attackers can execute arbitrary shell commands through controlled user input.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Wiz
CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-14831 [HIGH] CVE-2025-14831 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14831 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).
Source : NVD
## 5.3
Score
Published February 9, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libgnutls30-32bit
gnutls-guile
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
Wiz
CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.0
CVE-2025-9820 [MEDIUM] CVE-2025-9820 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-9820 :
GnuTLS vulnerability analysis and mitigation
A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error can cause the application using GnuTLS to crash or, in certain conditions, be exploited for code execution. As a result, systems or applications relying on GnuTLS may be vulnerable to a denial of service or local privilege escalation attacks.
Source : NVD
## 4
Score
Published January 26, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
GnuTLS
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1584 [HIGH] CVE-2026-1584 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1584 :
GnuTLS vulnerability analysis and mitigation
A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server.
Source : NVD
Published February 10, 2026
CNA Score N/A
Affected Technologies
GnuTLS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
gnutls-c++-debuginfo
gnutls-dane-debuginfo
Sources
NVD
Alpine 3.20, 3.21, 3.22, 3.23 Has Fix Added at: Feb 24, 2026
Alpine edge Has Fix Added at: Feb 11, 2026
Debian 14 Has Fix Added at: Feb 10, 2026
Debian Has Fix Added at: Feb 11, 2026
## Get a CVE risk assess
Bugzilla
CVE-2026-1584 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
bugzilla·2026-01-29·CVSS 7.5
CVE-2026-1584 [HIGH] CVE-2026-1584 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
CVE-2026-1584 gnutls: gnutls: Remote Denial of Service via crafted ClientHello with invalid PSK binder
Summarysummary
A malicious TLS client can trigger a NULL pointer dereference on the server by sending a crafted ClientHello message with an invalid PSK binder value. This leads to a server crash and constitutes a remote Denial-of-Service condition.
Technical Detailstechnical-details
The issue occurs during PSK binder verification in the server-side code path.
In pre_shared_key.c, when the server receives a pre_shared_key extension, the function _gnutls_psk_recv_params() is invoked. Under certain conditions, the following logic is executed:
pskcred = (gnutls_psk_server_credentials_t) _gnutls_get_cred(session, GNUTLS_CRD_PSK); if (pskcred == NULL && (session->internals.flags & GNUTLS_NO
https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2026-1584https://bugzilla.redhat.com/show_bug.cgi?id=2435258https://access.redhat.com/errata/RHSA-2026:7477https://access.redhat.com/security/cve/CVE-2026-1584https://bugzilla.redhat.com/show_bug.cgi?id=2435258https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1584.json
2026-04-09
Published